Skip to main content

Purpose-built model for leaked secret detection

By Steven Van ·

Existing AI-detected alerts stay included in GHSP and GHAS, while new opt-in checks will consume GitHub AI Credits.

Customers using AI-detected Password alerts in GitHub have automatically moved to a new model that reads surrounding code to identify likely credentials, including passwords without a recognizable token format. The model detects secrets without generating code or prose.

Alerts and push protection

AI-detected secret alerts remain included in GitHub Secret Protection (GHSP) and GitHub Advanced Security (GHAS) at no additional charge. The model will also bring AI-detected alerts to GitHub Enterprise Server 3.23 in public preview, included with an enterprise’s existing GHSP and GHAS purchase.

AI-detected secrets in push protection are available in private preview. These checks look for unstructured credentials at push time, giving developers a chance to remove a secret before it enters repository history.

Secret scanning in security reviews

AI-based secret scanning through the Copilot CLI and Copilot app’s /security-review command is coming soon in private preview. The command itself is already in public preview. The app documentation describes running it in an active session with in-progress code changes to receive prioritized vulnerability findings, severity and confidence scores, and suggested fixes that can be applied and verified in the same session.

Credits for opt-in checks

The new opt-in push protection and security review checks will consume GitHub AI Credits, with credit usage introduced in the coming weeks. Existing AI-detected secret alert scans remain included in GHSP and GHAS without an additional charge.

GitHub
GitHub
Where the world builds software — Git hosting, pull requests, issues, Actions CI/CD, and Copilot, free for public and private repos.
View GitHub →

Original source

Read Purpose-built model for leaked secret detection on Creators Toolbox